WS-2023-0176
Published:May 20, 2026
Updated:May 20, 2026
Path Traversal vulnerability in PHP LocalVolumeDriver connector
Affected Packages
lionbridge.flexframe.webui (NUGET):
Affected version(s) =1.0.0Fix Suggestion:
Update to version no_fixttek/tk-base (PHP):
Affected version(s) =3.2.110 <3.2.112Fix Suggestion:
Update to version 3.2.112playground/design (PHP):
Affected version(s) >=1.1.1 <1.2.1Fix Suggestion:
Update to version 1.2.1herurahmat/rimbun (PHP):
Affected version(s) >=1.0.2 <=1.0.3Fix Suggestion:
Update to version no_fixbigbrush/yii2-big (PHP):
Affected version(s) =1.2.10Fix Suggestion:
Update to version no_fixnova-framework/framework (PHP):
Affected version(s) =v4.0.0 <4.0.1Fix Suggestion:
Update to version 4.0.1laraflat/laraflat (PHP):
Affected version(s) >=dev-dev <=3.0.0Fix Suggestion:
Update to version no_fixttek/tk-base (PHP):
Affected version(s) >=3.0.64 <3.0.76Fix Suggestion:
Update to version 3.0.76ecnet/admin (PHP):
Affected version(s) =dev-master <1.0Fix Suggestion:
Update to version 1.0studio-42/elfinder (PHP):
Affected version(s) >=dev-master <1.0.1Fix Suggestion:
Update to version 1.0.1recca0120/elfinder (PHP):
Affected version(s) =v1.1 <v1.1.1Fix Suggestion:
Update to version v1.1.1components/elfinder (PHP):
Affected version(s) =2.2 <3.0-alphaFix Suggestion:
Update to version 3.0-alpharob006/yii-elfinder2 (PHP):
Affected version(s) >=1.0.2 <1.1.3Fix Suggestion:
Update to version 1.1.3serhatozles/yii2-elfinder (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixhelios-ag/fm-elfinder (PHP):
Affected version(s) >=dev-master <1.0.1Fix Suggestion:
Update to version 1.0.1dirmax/zettaframework (PHP):
Affected version(s) >=v1.1.48 <=v1.1.55Fix Suggestion:
Update to version no_fixttek/tk-base (PHP):
Affected version(s) =dev-master <1.0.0Fix Suggestion:
Update to version 1.0.0ttek/tk-base (PHP):
Affected version(s) =3.2.102 <3.2.104Fix Suggestion:
Update to version 3.2.104imagecms/imagecms (PHP):
Affected version(s) >=v4.4 <v4.9Fix Suggestion:
Update to version v4.9wufeifei/grw (PHP):
Affected version(s) >=dev-developer <=dev-pr/29Fix Suggestion:
Update to version no_fixttek/tk-base (PHP):
Affected version(s) =3.2.106 <3.2.108Fix Suggestion:
Update to version 3.2.108genix/cms (PHP):
Affected version(s) >=v0.0.7-alpha <v1.1.12.x-devFix Suggestion:
Update to version v1.1.12.x-devofferel/storage (PHP):
Affected version(s) >=1.2.2 <=1.4.5Fix Suggestion:
Update to version no_fixstudio-42/elfinder (PHP):
Affected version(s) >=2.0-beta <2.1.x-devFix Suggestion:
Update to version 2.1.x-devskcms/admin-bundle (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixsimple-mvc-framework/v2 (PHP):
Affected version(s) =dev-master <v2.0-beta.1Fix Suggestion:
Update to version v2.0-beta.1mofei/oneone (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixruncmf/runbb-ext-markitup (PHP):
Affected version(s) >=dev-master <=0.1.0Fix Suggestion:
Update to version no_fixuom/tk-base (PHP):
Affected version(s) =1.0.138 <1.0.140Fix Suggestion:
Update to version 1.0.140copona/copona (PHP):
Affected version(s) =dev-EV-code-refactoring <dev-checkout_newFix Suggestion:
Update to version dev-checkout_newnova-framework/framework (PHP):
Affected version(s) >=v3.67.0 <v3.78.24Fix Suggestion:
Update to version v3.78.24simple-mvc-framework/v2 (PHP):
Affected version(s) >=v3.67.0 <v3.78.24Fix Suggestion:
Update to version v3.78.24ttek/tk-base (PHP):
Affected version(s) >=3.0.86 <3.0.98Fix Suggestion:
Update to version 3.0.98simple-mvc-framework/v2 (PHP):
Affected version(s) =v4.0.0 <4.0.1Fix Suggestion:
Update to version 4.0.1ttek/tk-base (PHP):
Affected version(s) >=3.0.100 <3.2.64Fix Suggestion:
Update to version 3.2.64basdog22/laracms (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixalxishin/elfinder (PHP):
Affected version(s) >=dev-master <=2.1.59.1Fix Suggestion:
Update to version no_fixnickbur/sunrisecms (PHP):
Affected version(s) =v1.0.0Fix Suggestion:
Update to version no_fixttek/tk-base (PHP):
Affected version(s) >=3.0.50 <3.0.62Fix Suggestion:
Update to version 3.0.62nova-framework/cms (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixstudio-42/elfinder (PHP):
Affected version(s) >=dev-2.1-src <2.1.41Fix Suggestion:
Update to version 2.1.41nova-framework/novacms (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixgekomod/files-bundle (PHP):
Affected version(s) =dev-master <0.2Fix Suggestion:
Update to version 0.2ttek/tk-base (PHP):
Affected version(s) >=3.0.78 <3.0.84Fix Suggestion:
Update to version 3.0.84bigbrush/yii2-big (PHP):
Affected version(s) >=1.1.0 <1.2.9Fix Suggestion:
Update to version 1.2.9maddoger/yii2-elfinder (PHP):
Affected version(s) =v1.1Fix Suggestion:
Update to version no_fixgyman/supr (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixsiteforever/site-forever-cms (PHP):
Affected version(s) =0.4.1.x-dev <0.5.x-devFix Suggestion:
Update to version 0.5.x-devwhole/core (PHP):
Affected version(s) >=dev-localization <=1.1.3.2Fix Suggestion:
Update to version no_fixttek/tk-base (PHP):
Affected version(s) >=3.0.30 <3.0.42Fix Suggestion:
Update to version 3.0.42ttek/tk-base (PHP):
Affected version(s) >=1.0.52 <1.0.156Fix Suggestion:
Update to version 1.0.156gekomod/files-bundle (PHP):
Affected version(s) >=1.1.0 <=1.1.1Fix Suggestion:
Update to version no_fixplayground/playground (PHP):
Affected version(s) >=1.1.1 <=2.2.0Fix Suggestion:
Update to version no_fixcopona/copona (PHP):
Affected version(s) =dev-media-manager <dev-newcartFix Suggestion:
Update to version dev-newcartsilverkix/cms-bundle (PHP):
Affected version(s) >=dev-master <=dev-1.0.0-betaFix Suggestion:
Update to version no_fixci4-cms-erp/ci4ms (PHP):
Affected version(s) >=dev-breadcrumbs <dev-masterFix Suggestion:
Update to version dev-masteralphalemon/elfinder-bundle (PHP):
Affected version(s) =dev-master <1.0.0Fix Suggestion:
Update to version 1.0.0dirmax/zettaframework (PHP):
Affected version(s) >=v1.1.44 <v1.1.46Fix Suggestion:
Update to version v1.1.46dirmax/zettaframework (PHP):
Affected version(s) >=v0.1 <v1.0Fix Suggestion:
Update to version v1.0nao-pon/elfinder-nightly (PHP):
Affected version(s) =2.0.x-dev <dev-2.0_nFix Suggestion:
Update to version dev-2.0_nnickbur/divinecms (PHP):
Affected version(s) =v1.0.0Fix Suggestion:
Update to version no_fixredkite-labs/redkite-cms (PHP):
Affected version(s) >=v1.1.3 <1.1.3.5Fix Suggestion:
Update to version 1.1.3.5basdog22/laracms_nopublic (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixuom/tk-base (PHP):
Affected version(s) >=3.4.18 <=3.4.26Fix Suggestion:
Update to version no_fixgenix/cms (PHP):
Affected version(s) >=dev-dependabot/composer/phpmailer/phpmailer-6.5.0 <=dev-dependabot/composer/guzzlehttp/psr7-1.8.5Fix Suggestion:
Update to version no_fixrob006/yii-elfinder2 (PHP):
Affected version(s) >=1.1.4 <1.1.6Fix Suggestion:
Update to version 1.1.6dirmax/zettaframework (PHP):
Affected version(s) >=v1.1.41 <v1.1.43Fix Suggestion:
Update to version v1.1.43hgati/magento-1-page-builder-module (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixrob006/yii-elfinder2 (PHP):
Affected version(s) =dev-master <1.0.0Fix Suggestion:
Update to version 1.0.0romjkeeeen/fix-cms-core1 (PHP):
Affected version(s) >=dev-dev-master <=dev-php8-dev-masterFix Suggestion:
Update to version no_fixredkite-labs/redkite-labs-elfinder-bundle (PHP):
Affected version(s) =1.1.0-beta <1.1.x-devFix Suggestion:
Update to version 1.1.x-devttek/tk-base (PHP):
Affected version(s) =3.0.x-dev <3.0.2Fix Suggestion:
Update to version 3.0.2ttek/tk-base (PHP):
Affected version(s) >=3.2.128 <3.2.136Fix Suggestion:
Update to version 3.2.136bigbrush/yii2-big (PHP):
Affected version(s) =dev-master <1.0.0Fix Suggestion:
Update to version 1.0.0copona/copona (PHP):
Affected version(s) >=dev-orm-eloquent <dev-pdfFix Suggestion:
Update to version dev-pdfgenix/cms (PHP):
Affected version(s) >=dev-dependabot/composer/studio-42/elfinder-2.1.59 <v0.0.1Fix Suggestion:
Update to version v0.0.1studio-42/elfinder (PHP):
Affected version(s) >=2.1.50 <2.1.60Fix Suggestion:
Update to version 2.1.60copona/copona (PHP):
Affected version(s) =dev-guest2checkout <dev-dependabot/composer/twig/twig-2.14.11Fix Suggestion:
Update to version dev-dependabot/composer/twig/twig-2.14.11ttek/tk-base (PHP):
Affected version(s) >=3.2.72 <3.2.96Fix Suggestion:
Update to version 3.2.96redkite-labs/redkite-labs-elfinder-bundle (PHP):
Affected version(s) =v1.1.3.2 <1.1.3.5Fix Suggestion:
Update to version 1.1.3.5ttek/tk-base (PHP):
Affected version(s) >=3.2.142 <8.0.0Fix Suggestion:
Update to version 8.0.0tugumuda/helpers (PHP):
Affected version(s) >=dev-master <=5.4.x-devFix Suggestion:
Update to version no_fixa70838697/yii2elfinder (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixofferel/storage (PHP):
Affected version(s) >=dev-dev <1.0.1Fix Suggestion:
Update to version 1.0.1pkrs/pkrs-framework (PHP):
Affected version(s) >=0.1.5 <0.1.8Fix Suggestion:
Update to version 0.1.8uom/tk-base (PHP):
Affected version(s) >=3.4.6 <3.4.16Fix Suggestion:
Update to version 3.4.16phpffcms/ffcms-elfinder (PHP):
Affected version(s) >=dev-master <=1.0.0Fix Suggestion:
Update to version no_fixttek/tk-base (PHP):
Affected version(s) >=3.0.12 <3.0.24Fix Suggestion:
Update to version 3.0.24keltanas/site-forever-cms (PHP):
Affected version(s) =0.4.1.x-dev <0.5.x-devFix Suggestion:
Update to version 0.5.x-devnova-framework/framework (PHP):
Affected version(s) =dev-master <v2.0-beta.1Fix Suggestion:
Update to version v2.0-beta.1wtolk/adfm-elfinder (PHP):
Affected version(s) =dev-tinymce-elfinderFix Suggestion:
Update to version no_fixttek/tk-base (PHP):
Affected version(s) >=dev-ver1 <1.0.50Fix Suggestion:
Update to version 1.0.50adfab/core (PHP):
Affected version(s) >=dev-master <0.3.2Fix Suggestion:
Update to version 0.3.2rob006/yii-elfinder2 (PHP):
Affected version(s) =1.0.x-dev <1.0.1Fix Suggestion:
Update to version 1.0.1research-nk/rnk-elfinder-bundle (PHP):
Affected version(s) =dev-masterFix Suggestion:
Update to version no_fixci4-cms-erp/ci4ms (PHP):
Affected version(s) =dev-searchpage <0.21.0Fix Suggestion:
Update to version 0.21.0gekomod/files-admin-bundle (PHP):
Affected version(s) =1.0Fix Suggestion:
Update to version no_fixherurahmat/rimbunci3 (PHP):
Affected version(s) >=1.0.1 <=1.0.3Fix Suggestion:
Update to version no_fixmaddoger/yii2-elfinder (PHP):
Affected version(s) =dev-master <v.1.0.0Fix Suggestion:
Update to version v.1.0.0semisalov/fix-cms-core (PHP):
Affected version(s) >=dev-dev-master <=dev-php8-dev-masterFix Suggestion:
Update to version no_fixadfab/core (PHP):
Affected version(s) >=0.3.5 <=0.3.19Fix Suggestion:
Update to version no_fixyukisaw/elfinder (PHP):
Affected version(s) >=dev-filesize <=2.2.2Fix Suggestion:
Update to version no_fixredkite-labs/redkite-labs-elfinder-bundle (PHP):
Affected version(s) =v1.1.0 <v1.1.3Fix Suggestion:
Update to version v1.1.3Related Resources (1)
Do you need more information?
Contact UsCVSS v4
Base Score:
8.7
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
7.5
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE